Re: KASAN: slab-out-of-bounds Read in bpf_skb_change_head

From: Daniel Borkmann
Date: Wed Jun 13 2018 - 19:02:13 EST


On 06/14/2018 12:17 AM, syzbot wrote:
> Hello,
>
> syzbot found the following crash on:
>
> HEAD commit:ÂÂÂ 75d4e704fa8d netdev-FAQ: clarify DaveM's position for stab..
> git tree:ÂÂÂÂÂÂ bpf-next
> console output: https://syzkaller.appspot.com/x/log.txt?x=16bd21af800000
> kernel config:Â https://syzkaller.appspot.com/x/.config?x=a601a80fec461d44
> dashboard link: https://syzkaller.appspot.com/bug?extid=567faa843005dda30737
> compiler:ÂÂÂÂÂÂ gcc (GCC) 8.0.1 20180413 (experimental)
> syzkaller repro:https://syzkaller.appspot.com/x/repro.syz?x=1039185f800000
> C reproducer:ÂÂ https://syzkaller.appspot.com/x/repro.c?x=11e85cff800000
>
> IMPORTANT: if you fix the bug, please add the following tag to the commit:
> Reported-by: syzbot+567faa843005dda30737@xxxxxxxxxxxxxxxxxxxxxxxxx

#syz fix: bpf: reject passing modified ctx to helper functions